What Happened
CISA published advisory AA26-237A, comparing outcomes from two red team assessments run against separate organizations using closely matched attacker tradecraft. In one engagement, the red team gained an initial foothold on multiple workstations, escalated privileges across the domain, and moved laterally into sensitive business systems and cloud resources without triggering a single alert throughout the assessment. The advisory sets both engagements side by side, walking through the specific detection and response gaps separating an organization catching an intrusion early from one missing it entirely. CISA frames the document as a practical companion for security teams benchmarking their own detection coverage against realistic attacker behavior rather than theoretical threat models.
Why This Matters for Canadian Organizations
Canadian critical infrastructure operators, financial institutions, and government agencies face the exact detection and response gaps CISA outlines here, and the Canadian Centre for Cyber Security has issued comparable guidance urging organizations to validate defenses against realistic adversary tradecraft rather than compliance checklists alone. Under Bill C-26, designated critical infrastructure operators carry obligations to identify and address cybersecurity gaps proactively, and a red team engagement modeled on CISA’s approach offers a concrete way to test whether existing detection tooling performs as expected against lateral movement and privilege escalation techniques attackers use daily.
What to Do
Security teams should treat the advisory as a checklist, reviewing logging coverage across domain controllers, cloud identity providers, and business-critical applications for the specific gaps CISA documents. Organizations lacking a recent red team or purple team engagement should prioritize scheduling one, since the advisory demonstrates how two similarly resourced organizations produced dramatically different outcomes based on configuration and monitoring choices rather than budget alone. The full advisory, including detailed technical findings, is available from CISA.






